I would suggest startups are the wrong area. Startups barely have money to pay for staff and often don't know or care about their security risk. They also tend to use tools which allay some of that risk (eg: Stripe, etc for credit cards, non-storage of PCI-Compliant data). Mid-Sized companies often have sensitive data, older techniques, and/or budget - and can be convinced of their risk. I would suggest going the routes of medium size business up to lower Fortune 3000 companies. Reason, the CISO position is increasingly going to those in security with Penetration background rather than other areas of sercurity (eg: physical, Identity & Access, etc). You might look at a strategy similar to http://Phishme.com which is selling into larger accounts.
[my background: used to implement and sell security into Fortune 1000 account and SMB's]